Agent skill

Re Attribution

by dslsdzc in dslsdzc/rev-skills

威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.

Apache-2.0Auto-check passedSecurity

Install Re Attribution

skills CLI
$ npx skills add dslsdzc/rev-skills --skill re-attribution -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dslsdzc/rev-skills re-attribution --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-attribution .claude/skills/re-attribution && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
re-attribution
GitHub stars
125
Used in
1 other repo
Token cost
~1.1k tokens
SKILL.md length
237 words
Files
3 (incl. references)
Skills in repo
41
Repo updated
First seen
Licence
Apache-2.0

At a glance

威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.

  • Works in 5 steps: 钻石模型定位 → 基础设施图谱 → 能力与样本归因 → …
  • Security work in your project
  • SKILL.md covers 何时使用 / 何时不用, 工具准备, 操作步骤 and 跨域联合, plus 1 more section
  • Calls apt, pip and python3

What it does

Re Attribution is an agent skill from dslsdzc/rev-skills. 威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告。 触发词:归因、APT、attribution、攻击者身份、基础设施图谱、钻石模型、威胁组织。

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/decision-tree.md` and `references/gotchas.md`).

It sits in Security. It works with Python. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.

When your agent uses it

  • Security work in your project

Example prompts

  • “/re-attribution”

Requirements

  • Python 3
  • Docker

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. 钻石模型定位
  2. 基础设施图谱
  3. 能力与样本归因
  4. 置信度分级
  5. 报告

What it can do on your machine

Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • apt
    • pip
    • python3
    • dnf
    • brew
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Re Attribution loads about 1.1k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 23 tokens; SKILL.md has 237 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~23
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 237 words, ~1,106 tokens.

Download SKILL.mdSave it as .claude/skills/re-attribution/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
re-attribution
description
威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告。 触发词:归因、APT、attribution、攻击者身份、基础设施图谱、钻石模型、威胁组织。
type
atomic
capabilities
threat-intel

威胁归因(APT Attribution)

何时使用 / 何时不用

  • 用:情报归因请求(「谁干的」)、多事件串并(判断几起事件是否同一活动)、基础设施关联分析、样本/能力到攻击者的推理
  • 用:受害环境的攻击者画像(时间线、TTP、基础设施特征综合)
  • 用:同组活动排查(一次事件 → 找同基础设施/同能力的其他事件,先关联再定级)
  • 不用:单个 IOC 查询(转 [[re-ti]]);恶意行为判定(转 [[re-behavior]])
  • 不用:司法证据链(刑事标准高于情报归因,本技能结论不能直接作为司法证据,见 [[gotchas]])
  • 不用:只有单角证据时做组织级归因(仅样本或仅域名不支撑归因声明,分支判断见 [[decision-tree]])

工具准备

关联查询工具(Passive DNS / 证书透明 / Whois)
  • whois CLI(注册信息/ASN 归属):Linux apt install whois / dnf install whois;macOS brew install whois;Windows 用 WSL 分支(见 [[re-analyze/platform-tips]])
  • python-whois(Python 模块):多平台 pip install python-whois;验证: python3 -c "import whois"
  • dnsx(DNS 枚举):官方渠道为 Go 二进制——GitHub projectdiscovery/dnsx releases 或 go install github.com/projectdiscovery/dnsx/cmd/dnsx@latest;验证 dnsx -version(PyPI 同名包与官方工具无关,别混用)
  • 证书透明日志:crt.sh 网页查询(公开服务,按域名/证书指纹检索)
  • ASN 归属查询:whois -h whois.cymru.com <IP> 返回 AS 号与归属(Team Cymru 公开接口)
MISP(情报关联与共享)
  • Docker 部署(官方安装脚本/镜像,apt install misp 在发行版源不存在)或轻量替代(本地 CSV/图文件)
  • 验证: 登录 MISP UI 能创建/检索事件(轻量替代用数据导入脚本自检)
图分析(基础设施关系)
  • 多平台: pip install networkx(python 图分析);验证: python3 -c "import networkx"

操作步骤

按顺序执行;全部内容脱敏处理(红线:不指向具体组织/受害者身份,只用代号与抽象描述)。

  1. 钻石模型定位:

    • 四角:受害者(已明确)/ 基础设施(C2 域名/IP/证书)/ 能力(工具/样本/漏洞利用)/ 对手(待推断)
    • 活动线:把事件建模为元组(时间、对手、能力、基础设施、受害者),多事件按共享元素连成活动线
    • 元数据要素:时间窗、受害域、行业属性——用于聚类与时间线(不单独作证据)
    • 四角信息表字段:每角列(已知项/未知项/来源/查询时间),未知项就是归因缺口
    • 产出:四角已知信息表 + 缺失角(归因目标)
    • 规则:只有两角以上才能开始推理;单角(仅样本)不支撑归因声明(判据见 [[decision-tree]])
    • 单角输出形态:只有 1 角时交付「情报线索」级(IOC 清单 + 特征描述),标注「未进入归因」,不写组织名
  2. 基础设施图谱:

    sh
    # 域名/IP/证书关联聚类(示例流程,工具可替换)
    # 1) 收集 C2 域名/IP → whois 注册信息(注册者/邮箱/NS/ASN)
    # 2) 证书透明日志(crt.sh)查共用证书 → 关联其他域名
    # 3) dnsx 主动枚举关联子域/NS 记录(被动 DNS 接口看解析历史)
    # 4) networkx 图聚类:共享注册者/证书/NS/ASN 的节点合并
    • 聚类特征按区分度排序:唯一注册邮箱/证书 > 共用 NS/ASN > 同托管商
    • 被动 DNS 关注点:域名首次解析时间、解析 IP 段切换史、历史 NS 变化(注册人操作习惯特征)
    • IP 段特征:段内其他域名的用途/注册时间(同类活动聚集是弱线索,需排除托管商批量注册)
    • Whois 隐私保护:注册信息可能匿名(GDPR 后常见)——注册者字段不可用时降级用证书/NS/行为特征交叉,标注注册信息盲区
    • 域名相似性(同后缀/typosquat)只作弱线索:注册商与注册时间都可伪造
    • 跳板/托管商共存不能作为归属证据(见坑 1 与 [[gotchas]])
  3. 能力与样本归因:

    • 代码复用:样本间字符串/函数/资源/导入表相似度(唯一性字符串优先)
    • TTP 对比:行为模式与已知活动对齐(对齐方式参考 [[re-behavior]] 与 ATT&CK 映射)——先粗对齐(技术大类)再细对齐(端口/参数/加密细节)
    • 时间线:活动窗口对齐(先归一 UTC 核对时区与时间来源,见坑 6)
    • 唯一性特征优先:独特字符串/编译特征/语言习惯(比通用 TTP 更有区分度)
    • 样本家族名是分析人员命名,不是归属证据(命名由分析习惯决定,见 [[gotchas]])
    • 产出:能力证据表(每条证据 → 支持/反对假设,来源可追溯)
  4. 置信度分级:

    • 低:单类弱证据(特征泛化,如仅共享托管商)
    • 中:两类独立证据交叉,或单类强证据(多个唯一性特征)
    • 高:三类以上 + 时间线一致 + 无矛盾证据
    • 判定:按证据类型×强度打分,规则与反例见 [[decision-tree]] 证据分级表
    • 措辞规范:低→「关联活动」;中→「疑似同一活动」;高→「高度疑似归属」;不写绝对断言(见 [[gotchas]] 声明边界)
    • 规则:无高置信度证据时声明「关联活动」而非「归属组织」;明确列出未解决的反证
    • 不设「确认」级:情报归因无 100% 断言,最高等级也保留假设前提(如「假设该基础设施未被劫持」)
  5. 报告:

    • 结构:结论(分级声明)→ 证据链(每角证据 + 来源)→ 置信度依据 → 反证与未决项 → 方法边界(哪些无法判定)
    • 模板(脱敏版):
      # 归因报告(内部)
      - 结论:<等级> —— 与 <代号> 活动为同一活动方(置信度:中)
      - 证据链:1) 唯一注册邮箱(whois,查询时间) 2) 共用证书(crt.sh) 3) 代码唯一字符串(样本对照)
      - 反证/未决项:时间线缺口;注册信息匿名(GDPR)
      - 方法边界:未验证 C2 行为;无法判定项清单
    • 结论与证据对照 [[re-analyze/analysis-contract]] 复核格式存档(结论/证据/置信度)
    • 脱敏:不公开受害者身份/真实组织名(用代号),不发表过度归因声明;对外口径与内部结论分开(分层输出)
    • 脱敏检查清单:受害者身份/组织名/域名/IP 全替换代号;截图中的主机名/用户名打码;引用原始情报前重查一遍

跨域联合

  • [[re-ti]]:情报输入(IOC 查询与背景)
  • [[re-ioc]]:指标提取(域名/IP/哈希)
  • [[re-behavior]]:行为证据(TTP 对齐)
  • [[re-protocol]]:C2 协议分析(基础设施特征)
  • [[re-hunting]]:归因假设可转狩猎假设(「如果同一活动方进入环境,会在遥测中出现什么」)
  • [[re-feedback]]:归因案例经验沉淀(脱敏后)
  • [[re-analyze/analysis-contract]]:结论交付格式

常见坑与陷阱

  • 基础设施重叠导致误归因:现象——两活动共享 C2 基础设施被并为一组;原因——共用托管/被劫持基础设施;对策——区分「共享」与「控制」证据(注册信息 vs 仅托管),共享类证据降级为弱证据
  • 跳板机 ≠ 归属:现象——经第三方跳板的活动归到跳板所有者;原因——混淆路径;对策——只把「控制面证据」(注册/配置/唯一特征)算入归属
  • 置信度虚高:现象——单一独特性状(罕见字符串)即高置信度;原因——单证据强但无交叉验证;对策——按步骤 4 分级,单类弱证据最高「低」,单类强证据最高「中」
  • 能力共享被误读:现象——两家活动共用工具(公开工具/租赁平台)被归为一家;原因——能力是商品化资源,不唯一;对策——工具类证据只能作弱证据,需叠加基础设施/时间线证据
  • 无证据 ≠ 排除:现象——时间线对不齐/查不到记录即判断「无关」;原因——被动数据缺失、证据未公开;对策——标注「未发现」而非「不存在」,时间线缺口列反证
  • 时间戳/日志反取证:现象——攻击者伪造时间戳/删除日志使时间线错位;原因——主动混淆;对策——多时间来源交叉(文件时间/日志/流量时间),标注可信度
  • 脱敏红线:现象——报告中出现真实受害者/组织身份;原因——复制原始情报未处理;对策——报告前逐项检查(红线强制)
  • 报告口径外泄:现象——内部结论被当作对外声明引用;原因——口径不分层;对策——内部报告与对外摘要分开版本,对外摘要只保留分级与证据概览
  • 推理链不可复核:现象——结论无法回溯到证据;原因——假设与中间判断未记录;对策——每步假设/证据/分级全程存档(路径+时间),报告附证据索引
  • 场景分支、证据分级表与更多反例见 [[decision-tree]] / [[gotchas]]

© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .claude/skills/re-attribution of dslsdzc/rev-skills.

  • SKILL.md
  • references/decision-tree.md
  • references/gotchas.md

Open the folder on GitHubat commit bd21db8

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in dslsdzc/rev-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Re Attribution next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Re Attribution compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Re Attribution this skilldslsdzc/rev-skills1251 repos~1.1kAutomated safety check: PassApache-2.0
C To AstNarwhal-Lab/MagicSkills316—~1.1kAutomated safety check: PassMIT
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT
Vpn Security CheckSergei-thinker/vpn-setup189—~1.5kAutomated safety check: NotesMIT
Banditalpha-omega-security/scrutineer231—~615Automated safety check: NotesMIT
Python Reviewliuyanghejerry/Clausura204—~164Automated safety check: PassMIT

Similar skills

  • C To Ast

    Narwhal-Lab/MagicSkills

    Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.

    316 GitHub stars~1.1k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Vpn Security Check

    Sergei-thinker/vpn-setup

    Infrastructure security audit for VPN server. An agent skill from Sergei-thinker/vpn-setup.

    189 GitHub stars~1.5k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Bandit

    alpha-omega-security/scrutineer

    Run bandit against the Python source in the repository and map its hits into the findings shape.

    231 GitHub stars~615 tokensUpdated yesterday
    SecurityAuto-check: notes
  • Python Review

    liuyanghejerry/Clausura

    Python 遗留代码审查:bare except、SQL 注入、反序列化、密钥、调试输出. An agent skill from liuyanghejerry/Clausura.

    204 GitHub stars~164 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Security Setup

    luongnv89/skills

    Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.

    131 GitHub stars~4.5k tokensUpdated yesterday
    SecurityAuto-check passed

More from dslsdzc/rev-skills

All 41 skills in this repo
  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    125 GitHub stars~2k tokensUpdated 3 days ago
    Auto-check passed
  • Re Fp Runtime

    dslsdzc/rev-skills

    函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Re Hypervisor

    dslsdzc/rev-skills

    虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。

    125 GitHub starsUsed in 1 repo~3.4k tokens
    Auto-check: notes
  • Re Sdr

    dslsdzc/rev-skills

    射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Re Uefi

    dslsdzc/rev-skills

    UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Re Cpp Abi

    dslsdzc/rev-skills

    现代 C++ 二进制逆向:RTTI/异常/虚表恢复、ABI 识别、mangling 解码. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~996 tokens
    Auto-check passed

Works with

Categories

Questions about Re Attribution

What does Re Attribution do?

威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills. Re Attribution is an agent skill from dslsdzc/rev-skills.

When should I use Re Attribution?

Re Attribution fits situations like: security work in your project.

How do I install Re Attribution in Claude Code?

Run `npx skills add dslsdzc/rev-skills --skill re-attribution -a claude-code`. Or copy the skill folder (.claude/skills/re-attribution in dslsdzc/rev-skills) into .claude/skills/re-attribution in your project. Claude Code loads it when a task matches its description.

How do I install Re Attribution in Codex?

Run `npx skills add dslsdzc/rev-skills --skill re-attribution -a codex`. Or copy the skill folder (.claude/skills/re-attribution in dslsdzc/rev-skills) into .agents/skills/re-attribution in your project. Codex loads it when a task matches its description.

Can I use Re Attribution in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-attribution -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-attribution, .gemini/skills/re-attribution, .github/skills/re-attribution and .opencode/skills/re-attribution in your project.

What does Re Attribution need to run?

Going by SKILL.md and its folder, Re Attribution needs the command-line tools its instructions call (apt, pip, python3, dnf, brew and go). Our summary lists: Python 3; Docker.

Does Re Attribution access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Re Attribution safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Re Attribution use?

Re Attribution is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Re Attribution use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.

What are the alternatives to Re Attribution?

Skills that share tags, products or a category with Re Attribution: C To Ast (Narwhal-Lab/MagicSkills, 316 stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Vpn Security Check (Sergei-thinker/vpn-setup, 189 stars) and Bandit (alpha-omega-security/scrutineer, 231 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Re Attribution?

dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 125 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.

Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.